Children's National Medical Center
bd_6aee8ee7dcf1cd2f · schema v1 · pii pii-v1
Full breach record for Children's National Medical Center →3 incidents on fileChildren's National Medical Center (DC) reported to HHS on 2015-02-24 a Hacking/IT Incident affecting 18,000 individuals (described as over 20,000 in the narrative). Employees responded to phishing emails, enabling unauthorized access via compromised credentials. Breached information — located in Email systems — included demographic, clinical, and health insurance data, and a limited number of Social Security numbers. Exfiltration software was deployed by the attacker. The CE remediated accounts, removed exfil tools, enhanced firewall/email controls, retrained staff, and offered 12 months of free identity monitoring for SSN-affected individuals. OCR obtained assurances of corrective action completion.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Feb 24, 2015
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.